Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-10931

Опубликовано: 26 авг. 2019
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8
CVSS3: 8.1

Описание

An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

0.10.23-1
disco

ignored

end of life
eoan

not-affected

0.10.23-1
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

upstream

not-affected

debian: Fixed before initial upload to archive
xenial

DNE

Показывать по

EPSS

Процентиль: 40%
0.00183
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
больше 6 лет назад

An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.

CVSS3: 8.1
debian
больше 6 лет назад

An issue was discovered in the openssl crate before 0.9.0 for Rust. Th ...

CVSS3: 8.1
github
больше 4 лет назад

Improper Certificate Validation in openssl

EPSS

Процентиль: 40%
0.00183
Низкий

6.8 Medium

CVSS2

8.1 High

CVSS3